Exploiting Web3's Hidden Attack Surface: Universal XSS on Netlify's Next.js Library

from blog Blog | Sam Curry, | ↗ original
On August 24th, 2022, we reported a vulnerability to Netlify affecting their Next.js "netlify-ipx" repository which would allow an attacker to achieve persistent cross-site scripting and full-response server side request forgery on any website out of the box.